cd /news/ai-agents/hardcoded-mcp-credentials-found-in-p… · home topics ai-agents article
[ARTICLE · art-133398] src=helpnetsecurity.com ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

Hardcoded MCP credentials found in public GitHub files

Hush Security's report "The State of MCP Configuration: The Identity Security Gaps" found that 12% of credential slots in roughly 82,000 publicly accessible MCP configuration files on GitHub contained a hardcoded credential literal, potentially exposing credentials for connected services and systems. The research identified hardcoded API keys and access tokens used by AI coding tools in those public files.

by read1 min views3 publishedSep 18, 2026

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company analyzed around 82,000 configuration files and found that 12% of credential slots contained a hardcoded credential literal, potentially exposing credentials for connected services and systems. How the exposed credentials were identified Researchers searched … More

The post Hardcoded MCP credentials found in public GitHub files appeared first on Help Net Security.

── more in #ai-agents 4 stories · sorted by recency
── more on @hush security 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/hardcoded-mcp-creden…] indexed:0 read:1min 2026-09-18 ·